Side-by-side comparison of two Model Context Protocol servers — install paths, tools, quality signals, and directory engagement so you can pick the right one for Claude, Cursor, and other MCP clients.
vet-mcp checks open source packages—like those suggested by AI coding tools—for vulnerabilities and malicious code. It supports npm and PyPI, and runs locally via Docker or as a standalone binary for fast, automated vetting.
Exposes the RSigma Sigma detection-engineering toolkit to AI agents over stdio or Streamable HTTP with rsigma mcp serve. Tools to author, lint, validate, and convert Sigma detection rules, evaluate and explain detections against log events, and inspect correlation state, all backed by a native Rust engine.
Quality signal
52/100 (Fair)
48/100 (Fair)
Install path
Remote · high
npx · low
Engagement
3 0 0 1,096
1 0 0 128
Tools
Real-time malicious package detection via SafeDep CloudVulnerability analysis based on dependency usage evidencePolicy-as-code enforcement with CEL expressionsSupports npm, PyPI, Maven, Go, Ruby, Rust, PHP ecosystemsScans container images and SBOMsOutputs actionable reports in multiple formats